CVE-2014-0015: Haxx Curl

Medium severity, CVSS 4.0. EPSS: 5.6% chance of exploitation in the next 30 days.

cURL and libcurl 7.10.6 through 7.34.0, when more than one authentication method is enabled, re-uses NTLM connections, which might allow context-dependent attackers to authenticate as other users via a request.

Affected products

  • Haxx Curl: version 7.10.6 only; version 7.10.7 only; version 7.10.8 only; version 7.11.0 only; version 7.11.1 only; version 7.11.2 only; …
  • Haxx Libcurl: version 7.10.6 only; version 7.10.7 only; version 7.10.8 only; version 7.11.0 only; version 7.11.1 only; version 7.11.2 only; …

Published 2014-02-02. Last modified 2026-06-17.